---
id: CVE-2026-76722
title: >-
  Uncontrolled Format string vulnerabilities exist in the affected interface of
  HPE Networking Instant ON APs that could allow an unauthenticated remote
  attacker to run arbitrary commands on the underlying host
summary: >-
  Uncontrolled Format string vulnerabilities exist in the affected interface of
  HPE Networking Instant ON APs that could allow an unauthenticated remote
  attacker to run arbitrary commands on the underlying host. Successful
  exploitation cou…
severity: critical
cvss: 9.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'
vendor: Hewlett Packard Enterprise (HPE)
product: Instant ON
affected:
  - instant_on >= 0.0.0.0 <= 3.4.1.0
published: '2026-09-29'
updated: '2026-09-29'
sourceUpdated: '2026-09-29T21:39:02.570'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-76722'
references:
  - url: >-
      https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05150en_us&docLocale=en_US
    label: security-alert@hpe.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-09-29T19:44:04.157Z'
---

## Overview

Uncontrolled Format string vulnerabilities exist in the affected interface of HPE Networking Instant ON APs that could allow an unauthenticated remote attacker to run arbitrary commands on the underlying host. Successful exploitation could result in a Denial-of-service or potential remote code execution.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
